Malicious
Malicious

c1119345881aee09683576ffa959c4e9

PE Executable
MD5: c1119345881aee09683576ffa959c4e9
Size: 9.23 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c1119345881aee09683576ffa959c4e9
Sha1 24480249bf1d86059ccc84ac7c63c4a5be0c0126
Sha256 a158ac1913cdec970d074babc147c5d6406c0105e324bf61be59a7aad6c12a17
Sha384 a87efd40e113472f6f6d9e41aaaa143f4fda2810ea55655690c629ae9a7e5f70bf3c3363afe8e978222e4953cda87dba
Sha512 8b69e0d39e72ae3b3b7278bbfe6f792ebfe9beacde99b1b9832f84c9289b6fa6ec97200fc0ae5dd32d91017308855cf6277c566916bc6297af00379afeed1592
SSDeep 49152:ToHVmHat/2n9oeLgDkF+9tRoH0NM18wlX2NhAbcsqZTUaP6jc:TGf489+18wlX2/ocsqZP
TLSH F4967B07BEA108F9C1AAE33589AB4212BB74BC4D4B3233D32E50AA782F727D15D75754
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Overlay_8948767b.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_8948767b.bin (4617216 bytes)
Overlay_8948767b.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙