Suspicious
Suspect

1ba59aa7afc818d89c3a9b95c6d0b17e

PE Executable
MD5: 1ba59aa7afc818d89c3a9b95c6d0b17e
Size: 9.8 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1ba59aa7afc818d89c3a9b95c6d0b17e
Sha1 cec63672e82725c8111920f0672dcc4c05157106
Sha256 c5fefde3f122e8d04584bc34b2a357773f4a3ca35ba7988ca0f23a7b5f88cc08
Sha384 1b617c99c8dd75e8575f225efadfecdd9d05223fed5e3e463d3a43f2b7e7d316debac51eff9bcf4049f4824d34d324f6
Sha512 0e83738ba2a0b2221c317100a51096484ea1a2a5d471ca361dbb429a362c4defdfceb207122768ffac7f01ccf4eae74ed356a97b0a033ae893f6810264236562
SSDeep 196608:KGQqc8VYjRnFm7hZ3JS/T5IIkmw/Yur44iIn6D:vBSohZ3wNIIkZ3r4OnA
TLSH 37A68D01FD8B95F6E9031A314167B27F63345D058F28CBDBEB847F6AE9772A10836249
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPeStubOEP v1.xPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙