Suspicious
Suspect

1fd1a9b422d596c9f37ce047e36fe893

PE Executable
MD5: 1fd1a9b422d596c9f37ce047e36fe893
Size: 6.56 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1fd1a9b422d596c9f37ce047e36fe893
Sha1 a9a43f8aa7416da86457140b8e9ddcc3001ae940
Sha256 e59ca9b29c4693354aed343f6521ddccd70b3a87f8ba5c490e602e6c81b625ff
Sha384 fa5ec5bbef99ae145ae92a546caeb10dcda021df5922c2300fbcde5597492ae9ab94951faa700cd0305d4790a99d4119
Sha512 24739e01993b6c8c299beac905395adf64514c8ebc260896219b0120db5dcbf9781cf4ccab03bbad76b8f837f15509ed8398e1dd7bce8f1a1ca6531fdd40cfb4
SSDeep 98304:CneDJRceiBEw2KRHtXLLcdVfDFln+eh9dLZQg3JVQwtr31:xceiBEw2KRHtXLLQfXnBLZQg3P
TLSH DF66AE03F9A555A5C29BA635C9E6C602B731BD094B33A3E72E50B73C2F767C099B9700
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_242d4040.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
4
19
32
46
65
78
90
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x63F400 size 8200 bytes
[Authenticode]_242d4040.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
4
19
32
46
65
78
90
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙