Suspicious
Suspect

5249cf70abf5c4da100a5b029bd75537

PE Executable
MD5: 5249cf70abf5c4da100a5b029bd75537
Size: 5 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 5249cf70abf5c4da100a5b029bd75537
Sha1 dff32ffe17559d09ff0ac1d36487d3b7242de64a
Sha256 c38ac8274a1612f035a43bbc7d9453961603545b911bb036b9edb239130eb0ad
Sha384 c7982abf2de8eaf1e1536568fba69177c01eea8a3cc19900211c1038aa9bd17ee9ed609d8f6dcc5dfbf6bd4cd85d72e3
Sha512 2016ffa1756bd7a6d44c6954e063acba2ab83599b8efdeb90b0503ce3682dc281bc1c3040f4e4313215e88a02f8a138018fae038b5395c925c2a47f2ab7d94e2
SSDeep 49152:uFKpz7i7FAlc03DCBGcm+a1h6TczyJPj4RRHrYvAaaU:uc3XND1aJrCOkU
TLSH 21366B03EEA548F9D296D73588774242B764BC499B3533D32E60BA742F363D0AE79B40
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙