Suspicious
Suspect

05115f6395eea7899fbf157247166559

PE Executable
MD5: 05115f6395eea7899fbf157247166559
Size: 2.97 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 05115f6395eea7899fbf157247166559
Sha1 86350494591be5d6a0f769ee2b99c3ec62df4488
Sha256 bf1e307ac3c2d2a7e9c5b30b181d196888b1c2f3a01e5bc508e5f39e71c0275c
Sha384 a83b7534f064fc44323a9856811a7bb45954fc80e7174b5501b7a2aee6ec444e258b62eafe06a488d565cf7597c6f5a9
Sha512 747b023447ae039625f702e95b1c71c5dbb2fbc0e5d6d6674247b47ae58a2cc613c98a90e757e2cac1b6e8291c112fd939072e743ad133dcde06b219410e8cdd
SSDeep 24576:Sl1dCBWgNhmPccaMfWaxebBdBD7McHHnqn9aIoyVwtF39RGXwZXtdezah3WP2LQu:Sl7QWQata2nwB7zHI2dYPJc3Vb
TLSH 03D58C0BAED909FED08697718DB392413676BE194B7A27C32D4033382E367D1AC75B49
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_6a1d36e2.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2D4C00 size 2392 bytes
[Authenticode]_6a1d36e2.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙