Suspicious
Suspect

db1cdbdc30d7056eecab4157714e8e43

PE Executable
MD5: db1cdbdc30d7056eecab4157714e8e43
Size: 12.57 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 db1cdbdc30d7056eecab4157714e8e43
Sha1 9997e4c7b6cdcee95143e7b410992746f17162e5
Sha256 bb24b382d5de5194bbb4cdf6d8127a3e82a205ccad251bcbc19100f876cd64d7
Sha384 222844b6f0a3c75d217cf6ec1de97b530bc28a145cf800a42c22e323eb9e02ee6fac1696dd471c36fe3227f70f7d61f7
Sha512 28085f3c836897114ca93dc5a314dd88e7703a3b3f3debeede1d0d172aef899b17e589600b5c1195a1eb2f39f6f8dd1f1b43cea2fabdc13f052449127d526bff
SSDeep 98304:fUhSHKu1UL+2iy0NeDqgdnt4bc3HX+LElO/:ou1y0op5tDhlO/
TLSH 0CC66C11FACB54F5E9035831406BB27F23315D048B28DBDBEB183B6AF87B6A1197A705
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPeStubOEP v1.xPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙