Suspicious
Suspect

1eeb3ebf665197ce9a35fc1ac745c118

PE Executable
MD5: 1eeb3ebf665197ce9a35fc1ac745c118
Size: 6.63 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1eeb3ebf665197ce9a35fc1ac745c118
Sha1 2b8ed70633be6e539cbdf7ac60b770aece2442c8
Sha256 edd33db4a56d62fc653f67fc589d3421a2ce6678b4a28f85077f9200d8f2ea8b
Sha384 5ec24e6c784318e4e880a07139a052ccd6b73fe898ca7d5a7275753714660b3ad66a30cc7c03f9cac0c83d2f4bcea17e
Sha512 84bfea5a26e88fd31634bf0ed5012a3f89372f854f34c2601d4a4ae51d867630fe5c572aaa381a21bf2d0742073a298dea76108bcbfa4a09e07ef55602541e42
SSDeep 49152:L24aKFtcsHcQQSXnf3ngE1Dh3Y9NJYbqmmwqw9W0lKBwss+/SJLvXlDctrM2BNcB:8uJpqjLK9LvJcPcs7H/0pA6S+fXuy
TLSH 8B664B41BA6B58BCD557C87487468A239E2130DB0B36BAFF018486383F6ABF15B3D754
PeID
MASM/TASM - sig4 (h)Microsoft Visual C++ 8.0 (DLL)Microsoft Visual C++ v6.0 DLLPe123 v2006.4.4-4.12Private EXE Protector V2.30-V2.3X -> SetiSoft Team
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: IT_solutions.pdb
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙