Suspicious
Suspect

1fb3eb94a79ce949ad409fff52b3f5f6

PE Executable
MD5: 1fb3eb94a79ce949ad409fff52b3f5f6
Size: 3.56 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1fb3eb94a79ce949ad409fff52b3f5f6
Sha1 fd679a6386bc8dc877a130e1988d9d5d75bb6060
Sha256 4357b8fd6eeecbcd40a0a7e3e6097fd050f378d97ea692f57537a9bba3f1d0f3
Sha384 1d9f18b69dd69f02f2cbd6d7ccf893512f7761eeb7f37cccbb5f74a1243cbf673831fd6c35c768c3b09b1d591cce9572
Sha512 f9e1c7b7473512e2c4a94b9269e1537a90bec14edc18854ddf4cb817fe88cd1b007ee1da45953520ea9c13661dd9297dede8e88ef677419ff10cf8d39949dbb3
SSDeep 49152:gfLhIgdrmNapWSIFab7TcgGXJ2qPWDY5k1nmQKY9Ly7UZ:g1ul595knl7
TLSH FDF57B0BBE9048E4C09EA23289675596BB35BC4D0B3633E32E51BA783FB27D05D35B54
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_27d16d77.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x363E00 size 2384 bytes
[Authenticode]_27d16d77.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙