Malicious
Malicious

1ef3b937304ab162d62bb3a6101f8b6e

PE Executable
MD5: 1ef3b937304ab162d62bb3a6101f8b6e
Size: 14.27 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1ef3b937304ab162d62bb3a6101f8b6e
Sha1 50e395603733ae8eed556e1b2dbf69707735a33a
Sha256 512cad03d60dcfd9484cfc331da2650b3d5cb2a9870f8948f314bc29ba952d44
Sha384 9cc7a490fab80a27c421de2cbeaed3442e6b08a6b9d7057268bb79ed7dad2d2c062ebf0f62a085d3bde9b267f2e19a1e
Sha512 af86a26b1d2ac1e2d39c9f5132399f11d64f3a059de917736405a2b57159f0a78c1ef97d7234c242dde0004355b64b10b377752c6b7d52585330e26b7fd4dfdb
SSDeep 393216:gI/wSy/bHGDvH24kMX1NgbyjUYdn3tKtJuKdZtMuE6KVzV06Un1RseuIl4q1cisf:JCyrxb
TLSH 94E65B83698604FAC581AE39C4779331B5A9B8BEC73037B73E5496B42F323D0A979744
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_89cd3580.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xD99000 size 8088 bytes
[Authenticode]_89cd3580.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙