Suspicious
Suspect

bd2654e2244bcf9a6a2252a13755a3ee

PE Executable
MD5: bd2654e2244bcf9a6a2252a13755a3ee
Size: 5 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bd2654e2244bcf9a6a2252a13755a3ee
Sha1 22827a2d38727640bef9a5bb4147984d7f8c081b
Sha256 d7934bfa4e1d52ff336ddc7ee231f206a1eb1ac286e5dd74e5d13ea12f824336
Sha384 4a2002b618f6f6970a9ceaeca7652dc393c402cc870dd4f5bdf787f91ab1ae37950a70006fcf6491572b75e84268e4f8
Sha512 7fdcad30d1eac4bd29f81c065f66adcabcfee01e53a3239f80d8e133e1ce640eeebbf082e817cb973cfb157bfcb8f6c1909938933500fa0a82b693493d1f4216
SSDeep 49152:uFKpz7i7FAlc03DCBGcm+a1h6TczyJPj4RRHrYvAaa+:uc3XND1aJrCOk+
TLSH 37366B03EEA548F9D296D73588774242B764BC499B3533D32E60BA742F363D0AE79B40
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙