Malicious
Malicious

1e1d111b87fc523c8b46b13e0300bcc0

PE Executable
MD5: 1e1d111b87fc523c8b46b13e0300bcc0
Size: 7.09 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1e1d111b87fc523c8b46b13e0300bcc0
Sha1 86ceedd043ce1327474de648f09ba993094f7835
Sha256 e9951dbc13b4fb5a2fe7b26783d8495131edf77b4028a8bebf25ed02beaa8b5b
Sha384 e2db46b30ef6460e56a548733854bb498a83513c313d2ed3996060cd119e1c7a0248a3014c38ce95c7dbcf4650d36e4b
Sha512 59e8b34259b41a2feed79456e1a0bc9a07ef04afcd259085dc3c3b5698e2891f612785d797addca55c36c236fc5bba0e3291e751611f6d3d8fbcca3226ad4e40
SSDeep 49152:34KhOdon9y+KXfR7w2NCDzgVZ4YmYuVeqS10N3/b4hlGLnYEUdlnrCkJWAsSkxpM:3lv0XGl/b4hlGLnMtrCuWA62GFv6IZ8
TLSH 66667D07BD6505F8C0999734CAA743527B787C8D8B3277E72E506A782F7ABD0693A700
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_a87543c5.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x673C00 size 8120 bytes
[Authenticode]_a87543c5.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙