Malicious
Malicious

03ff2eb2b1d54c66b7b8ee7ad84f13c6

PE Executable
MD5: 03ff2eb2b1d54c66b7b8ee7ad84f13c6
Size: 4.84 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 03ff2eb2b1d54c66b7b8ee7ad84f13c6
Sha1 23a8e417188fa10923dce018a278f4abdecc139e
Sha256 7e6c18d1f36ea881e2029160438efad994040e41376e9b664858725523b659cd
Sha384 3da3fbb82cdfbe73f8ecb5baaf96f8b64a8a89ad757cf6ac31d9dbc1349dd2638c6add658d878926c22a9a095fc8e0ad
Sha512 7b59abce3fed54a9e66e745b0b41c65430b9586409a148ca9f747ed2b5665fd65805a84426bbd8ab01dfc3a7b7c2436723fe1f6ca461316565c2e00423ccd867
SSDeep 49152:C6E58ITkSKZodnbdtdS5Zjc8qZqdsVZeI2cD9:CtPnbdeQ8yqdUeg
TLSH B6267B43BCA14AB6E095A37188B75256B771BC081B3633D32EA0EB783E767D05E35B50
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_d298cf92.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055>bin
Shape pe:exe>bin
malicious 2 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x450A00 size 2416 bytes
[Authenticode]_d298cf92.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙